significant security risk
A risk-level characterization applied in security, privacy, and compliance contexts to a threat source, vulnerability, configuration, or actor whose assessed likelihood and potential impact together exceed an organization's or regulator's stated risk tolerance threshold — placing it in a priority tier that mandates active mitigation, escalation, or control action rather than acceptance or deferral. The concept underpins risk prioritization: quantifying or qualifying which risks must be addressed first, ensuring resources focus on the most consequential exposures. Frameworks including NIST RMF, FISMA, and CISA operational directives use the phrase descriptively — for example, CISA's Binding Operational Directive BOD 22-01 is titled "Reducing the Significant Risk of Known Exploited Vulnerabilities," treating it as a threshold marker, not a defined term — and the same pattern appears across HIPAA, ISO 27001, and CIS guidance, where "significant" functions as a calibrated severity qualifier aligned to each framework's impact and likelihood scales.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A risk-level characterization applied in security, privacy, and compliance contexts to a threat source, vulnerability, configuration, or actor whose assessed likelihood and potential impact together exceed an organization's or regulator's stated risk tolerance threshold — placing it in a priority tier that mandates active mitigation, escalation, or control action rather than acceptance or deferral. The concept underpins risk prioritization: quantifying or qualifying which risks must be addressed first, ensuring resources focus on the most consequential exposures. Frameworks including NIST RMF, FISMA, and CISA operational directives use the phrase descriptively — for example, CISA's Binding Operational Directive BOD 22-01 is titled "Reducing the Significant Risk of Known Exploited Vulnerabilities," treating it as a threshold marker, not a defined term — and the same pattern appears across HIPAA, ISO 27001, and CIS guidance, where "significant" functions as a calibrated severity qualifier aligned to each framework's impact and likelihood scales.DR-088 backfill from the noun definition column